CLIENT DATA PROCESSING AGREEMENT

Size: px
Start display at page:

Download "CLIENT DATA PROCESSING AGREEMENT"

Transcription

1 CLIENT DATA PROCESSING AGREEMENT This Data Processing Agreement for the Data Protection (the Agreement ) of Data Processed is entered into on./../ (hereinafter referred to as the Effective Date ) by and between: MOBIWEB LIMITED, a company incorporated under the laws of Hong Kong, having its registered offices at 111, How Ming Street, Futura Plaza, Room 2103, Kwun Tong, Hong Kong, under Registration Number: , duly represented by the signee, hereinafter referred to as MobiWeb and....., a company incorporated in.... under registration number... whose principal place of business is at., duly represented by the signee, hereinafter referred to as Company. Hereinafter individually referred to as a Party and jointly as the Parties. WHEREAS: - The Effective Date shall be the date on which this Agreement is signed by the Company and MobiWeb. - The Parties have entered into a services agreement, the Wholesale SMS and Voice Messaging Agreement (hereinafter Main Agreement. - Due to the Main Agreement, MobiWeb will process Personal Data for the Company, for the purpose of the conveyance of SMS messages and Voice messages, on behalf of the Company, as defined in the Main - Under EU regulation 2016/679 GDPR, depending on the role of the Company, MobiWeb will act accordingly: - When the Company is the Data Controller, MobiWeb will be the Data Processor of the Company. - The Company is the Data Controller that controls Personal Data, collecting consent, managing consent-revoking, enabling right to access to Data Subjects. - MobiWeb is the Data Processor, that processes Personal Data on behalf of and under the instruction of the Company (Data Controller) and MobiWeb transfers Personal Data to a Sub-Processor for the purpose of provision of the Services as set forth in the Main - When the Company is the Data Processor or the Data Sub-Processor, MobiWeb will be the Data Sub- Processor of the Company. - The Company is the Data Processor that processes Personal Data on behalf of and under the instruction of the Data Controller or is the Data Sub-Processor that processes Personal Data on behalf of and under the instruction of the Data Processor that processes Personal Data on behalf of the Data Controller. - MobiWeb is the Data Sub-Processor, that processes Personal Data on behalf of and under the instruction of the Company and MobiWeb transfers Personal Data to a Sub-Processor for the purpose of provision of the Services as set forth in the Main NOW THEREFORE, THE PARTIES HEREBY AGREE AS FOLLOWS: ARTICLE 1 - DEFINITIONS Words and phrases used in this Agreement have the following meanings: Agreement: Main Agreement: GDPR: Data Controller: The present Data Processing Agreement and all Annexes hereto. The Master The EU General Data Protection Regulation (EU) 2016/679 is a regulation in EU law on data protection and privacy for all individuals within the European Union. It replaces the prior Data Protection Directive (95/46/EC) of The natural or legal person, public authority, agency or other body which, alone or jointly with others, determines the purposes and means of the processing of Personal Data; where the purposes and means of such processing are determined by Union or Member State law, the Data Controller or the specific criteria for its Page 1 of 7

2 nomination may be provided for by Union or Member State law. Furthermore, Data Controller controls Personal Data, collecting consent, managing consent-revoking, enabling right to access to Data Subjects. Data Processor: The natural or legal person, public authority, agency or other body which processes Personal Data on behalf of the Data Controller. Furthermore, Data Processor processes Personal Data on behalf of and under the instruction of the Data Controller. Data Sub-Processor: Data Protection Law(s): Data Subject(s): EEA: Personal Data Breach: A Processor engaged by the Data Processor, for the purpose of carrying out specific processing activities on behalf of the Data Controller. the local and international data regulation(s) and legislation(s) that are in force in any part of the world. An identifiable natural person, one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person. The European Economic Area. A breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, personal data transmitted, stored or otherwise processed. Service(s): The conveyance of SMS messages and Voice messages, provisioned by MobiWeb to the Company, as defined in the Main Agreement Personal Data: Any information relating to a Data Subject. Data Processing: Any operation or set of operations which is performed on Personal Data or on sets of Personal Data, whether or not by automated means, such as collection, recording, organisation, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction. Processing Instructions: The instruction(s) as set forth by the Data Controller to the Data Processor, for Data Processing of Personal Data of Data Subjects, for the purpose of Data Processor, provisioning Services to the Data Controller. Data Provider: The Company, a controller (or, where permitted, a processor) that transfers personal data to MobiWeb for the provisioning of Services to the Company. ARTICLE 2 - SUBJECT 2.1 This Agreement forms part of the Master Agreement between MobiWeb and Company for the purpose of MobiWeb provisioning Services to the Company to reflect the Parties agreement with regard to the Data Processing of Personal Data. 2.2 By signing the Agreement, Company enters into this Agreement on behalf of itself and, to the extent required under applicable Data Protection Laws and GDPR, if and to the extent MobiWeb processes Personal Data that the Company provides and therefore qualifies as a Data Provider (Data Controller, Data Processor or Data Sub-Processor). 2.3 In the course of providing the Services to the Company pursuant to the Agreement, MobiWeb may Process Personal Data on behalf of the Company and the Parties agree to comply with the following provisions with respect to any Personal Data, each acting reasonably and in good faith. Page 2 of 7

3 ARTICLE 3 PERSONAL DATA PROCESSING 3.1 MobiWeb shall process Personal Data provided by the Company on behalf and in accordance to the written instructions of the Company, unless required otherwise by applicable Laws. 3.2 Company shall, in its use of the Services provisioned by MobiWeb, Process Personal Data in accordance with the requirements of Data Protection Laws and GDPR. For the avoidance of doubt, Company s instructions for the Processing of Personal Data shall comply with Data Protection Laws and GDPR. Company shall have sole responsibility for the accuracy, quality, legitimacy and legality of Personal Data Processing and the means by which Company acquired Personal Data. 3.3 The subject-matter of Personal Data Processing by MobiWeb is the provision and performance of the Services pursuant to the Agreement and Master The purpose of the Processing, the types of Personal Data and categories of Data Subjects Processed under this Agreement are further specified in Annex 1 of this 3.4 The Company hereby instructs MobiWeb to carry out part of the Processing. 3.5 In the event that MobiWeb believes that the Company s instructions conflict with Data Protection Laws and GDPR, MobiWeb will inform the Company and the company will amend the instructions accordingly. MobiWeb will not carry any processing instructions that conflict with GDPR and any Data Protection Laws. ARTICLE 4 PERSONNEL 4.1 MobiWeb shall ensure that its personnel engaged in the Processing of Personal Data are informed of the confidential nature of the Personal Data, have received appropriate training on their responsibilities and have executed written confidentiality agreements. MobiWeb shall ensure that such confidentiality obligations survive the termination of the personnel engagement and the 4.2 MobiWeb shall take commercially reasonable steps to ensure the reliability of any MobiWeb personnel engaged in the Processing of Personal Data. 4.3 MobiWeb shall ensure that MobiWeb s access to Personal Data is limited to those personnel who require such access to perform the 4.4 MobiWeb's Data Protection Team may be reached at dataprotection@solutions4mobiles.com or ARTICLE 5 - OBLIGATIONS 5.1 MobiWeb shall assist the Company in providing retrieval access, correction, delete and block to Personal Data processed to Data Subjects and Authorities, allowing Data Subjects to exercise their rights under GDPR and Data Protection Laws. 5.2 MobiWeb shall assist the Company in meeting its GDPR obligations in relation to the security of Processing, the notification of Personal Data Breaches and data protection impact assessments. 5.3 MobiWeb shall inform the Company immediately upon becoming aware of requests received directly by Data Subjects and Authorities. 5.4 MobiWeb shall provide information and data to the Company, to assist the Company in meeting its GDPR obligations. 5.5 MobiWeb shall delete or return all Personal Data to the Company as requested at the end of the Agreement, unless required for the performance of Services or required by applicable Laws and Regulations. 5.6 MobiWeb shall process Personal Data only to provide Company with the Services as described in the Master 5.7 MobiWeb shall provide at all times sufficient guarantees for its compliance with the requirements of the GDPR. Page 3 of 7

4 5.8 MobiWeb shall treat the Personal Data as strictly confidential, ensuring personnel authorised access and secure processing. 5.9 MobiWeb shall ensure data availability and restoration functionality to the Company. ARTICLE 6 AUDIT AND COMPLIANCE 6.1 MobiWeb shall cooperate with Authorities in accordance with GDPR requirements. 6.2 MobiWeb shall inform the Company immediately upon becoming aware of requests received by Authorities. 6.3 MobiWeb shall allow for and shall contribute to audits and inspections conducted by a Company appointed auditor. Subject to reasonable prior notice from Company to MobiWeb, the appointed auditor may enter the rooms or locations where the personal data is processed by MobiWeb and inspect, audit any relevant records, processes and systems, and copy any relevant Personal Data records to verify compliance with GDPR and Data Protection Laws. 6.4 Company agrees to pay any and all costs of the full audit processes that are initiated by the Company and audit processes initiated by Authorities due to services provisioned by MobiWeb to the Company, including costs of involved third-parties (auditors, data centres, etc.) and MobiWeb (personnel compensation, traveling expenses, etc.). 6.5 Company agrees that MobiWeb shall combine several audits in one single audit, in order to limit any impact on MobiWeb and third-parties operations. 6.6 MobiWeb shall fully cooperate and make available to Company on its demand all information that is necessary to demonstrate compliance with the GDPR obligations and obligations under this ARTICLE 7 - SECURITY AND DATA PROTECTION 7.1 MobiWeb shall take appropriate organizational and technical measures and policies to ensure security of Personal Data Processing and meet sufficient guarantees of protection and security standards, including measures aimed at protecting Personal Data against accidental or unlawful destruction or accidental loss, alteration, unauthorised disclosure or access, in particular where the Processing involves the transmission of Personal Data over a network, and against all unlawful forms of Processing. ARTICLE 8 PERSONAL DATA BREACH 8.1 MobiWeb maintains security incident management policies and procedures and shall notify Company without undue delay after becoming aware of the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to Company Data, including Personal Data, transmitted, stored or otherwise Processed by MobiWeb or its Sub-Processors of which MobiWeb becomes aware. MobiWeb shall make reasonable endeavours to identify the cause of such Personal Data Breach Incident and take those steps as MobiWeb deems necessary and reasonable in order to remediate the cause of such an Incident to the extent the remediation is within MobiWeb s reasonable control. The obligations herein shall not apply to incidents that are caused by Company, Company s Systems (Software and Hardware) or Company s Personnel. ARTICLE 9 - SUB-PROCESSORS 9.1 Company agrees that MobiWeb shall use Sub-Processors for the provision and performance of the Services pursuant to the Agreement and Master MobiWeb shall ensure that Sub-Processors involved in the Processing of Personal Data shall be capable of providing necessary operational and technical level to comply with the requirements of GDPR and Data Protection Laws. 9.2 MobiWeb shall inform the Company of any intended changes concerning the addition or replacement of other Sub-Processors, thereby giving the Company the opportunity to consent or object to such changes through written material or electronic form. MobiWeb shall not execute changes without the written consent of the Company. Page 4 of 7

5 9.3 The Company will fully indemnify and hold MobiWeb harmless against all direct and indirect losses, claims, damages, fees and expenses incurred as a result of delays in Company s consent to Sub- Processor changes proposed by MobiWeb. ARTICLE 10 LIABILITY AND INDEMNITY The Company shall indemnify and hold MobiWeb harmless against claims by Data Controllers, Data Processors, Data Sub-Processors, Data Subjects and/or penalties or fines imposed by an authority for which MobiWeb might become liable, due to an attributable failure by the Company to comply with the obligations under this Agreement and/or applicable Data Protection Laws MobiWeb shall indemnify and hold the Company harmless against claims by Data Controllers, Data Processors, Data Sub-Processors, Data Subjects and/or penalties or fines imposed by an authority for which the Company might become liable, due to an attributable failure by MobiWeb to comply with the obligations under this Agreement and/or applicable Data Protection Laws Company agrees to be held liable against all expenses, losses, costs and damages arising due to an attributable failure by the Company to comply with the obligations under this Agreement and/or applicable Data Protection Laws The Company shall have full and sole liability for all damages resulting from a failure on its part to comply with the Agreement, GDPR and Data Protection Laws. Company shall indemnify and hold MobiWeb harmless against all expenses, losses, costs and damages arising therefrom. Should any person to whom personal data relates lodge a claim for compensation against MobiWeb and such claim is due to the Company s failure to comply with the provisions of this Agreement, GDPR or Data Protection Laws, the Company agrees to assist and intervene in MobiWeb s defence upon MobiWeb s request and shall indemnify and hold MobiWeb harmless from and against all expenses, losses, costs and damages Any limitations of liability agreed elsewhere shall not apply to this ARTICLE 11 - APPLICABLE LAW AND JURISDICTION 11.1 This Agreement shall be governed by the laws of Switzerland and any dispute concerning the implementation or interpretation of this Agreement that cannot be settled amicably between the parties shall be submitted to a federal or state court of law having jurisdiction in Geneva, Switzerland. ARTICLE 12 - DURATION 12.1 This Agreement will enter into effect on the Effective Date and will remain effective regardless termination of the Upon the Company s request, MobiWeb shall return or destroy the Personal Data, unless required for the performance of Services or required by applicable Laws and Regulations. If MobiWeb is required to retain Personal Data, MobiWeb shall inform the company and both Parties agree to cooperate towards the best possible solution for both Parties. If the Master agreement is terminated, this Data Processing Agreement will expire automatically. ARTICLE 13 - AFTER DATA PROCESSING TERMINATION 13.1 MobiWeb shall guarantee the confidentiality of the Personal Data transferred and will not Process the Personal Data of the Company after the termination of the 13.2 MobiWeb agrees to allow and to contribute to audits and inspections, subject to Article 6 of this ARTICLE 14 ORDER OF PRECEDENCE 14.1 In the event of a conflict between the provisions of this Agreement and those of the Master Agreement in respect of the Processing and Protection of Data, the provisions of this Agreement will prevail. Except as expressly modified herein, all terms and conditions of the Agreement shall remain in full force and effect. Page 5 of 7

6 IN WITNESS WHEREOF, the Parties have executed this Master Agreement effective as of the Effective Date. SIGNED FOR AND ON BEHALF of MobiWeb Name: Title: SIGNED FOR AND ON BEHALF of Company Name: Title: Signature: Date: Signature: Date: Page 6 of 7

7 ANNEX 1: DETAILS OF PROCESSING OF COMPANY PERSONAL DATA This Annex 1 includes certain details of the Processing of Company Personal Data as required by Article 28(3) GDPR. SUBJECT AND DURATION OF THE PROCESSING OF COMPANY PERSONAL DATA The subject matter and duration of the Processing of the Company Personal Data are set out in the Master Agreement and this THE NATURE AND PURPOSE OF THE PROCESSING OF COMPANY PERSONAL DATA [Include descriptions here] Examples: SMS, One-Time PINs THE CATEGORIES OF DATA THE TYPES OF COMPANY PERSONAL DATA TO BE PROCESSED [Include list of data types here] Examples: MSISDN, IMSI THE CATEGORIES OF DATA SUBJECT TO WHOM THE COMPANY PERSONAL DATA RELATES [Include categories of data subjects here] Examples: Customers, Users THE OBLIGATIONS AND RIGHTS OF COMPANY The obligations and rights of Company and Company Affiliates are set out in the Master Agreement and this Page 7 of 7

GDPR DATA PROCESSING ADDENDUM INSTRUCTIONS FOR JOSTLE CUSTOMERS

GDPR DATA PROCESSING ADDENDUM INSTRUCTIONS FOR JOSTLE CUSTOMERS GDPR DATA PROCESSING ADDENDUM INSTRUCTIONS FOR JOSTLE CUSTOMERS WHO SHOULD EXECUTE THIS DPA: If you have determined that you qualify as a data controller under the GDPR, and need a data processing addendum

More information

HOW TO EXECUTE THIS DPA:

HOW TO EXECUTE THIS DPA: DATA PROCESSING ADDENDUM (GDPR, and EU Standard Contractual Clauses) (Rev. April 20, 2018) This Data Processing Addendum ( DPA ) forms part of the Master Subscription Agreement or other written or electronic

More information

DATA PROCESSING AGREEMENT/ADDENDUM

DATA PROCESSING AGREEMENT/ADDENDUM DATA PROCESSING AGREEMENT/ADDENDUM This Data Processing Agreement ( DPA ) is made and entered into as of this day of, 2018 forms part of our Terms and Conditions (available at www.storemaven.com/terms-of-service)

More information

DATA PROCESSING TERMS AND CONDITIONS

DATA PROCESSING TERMS AND CONDITIONS DATA PROCESSING TERMS AND CONDITIONS These Data Processing Terms and Conditions apply in respect of Personal Data that we process on behalf of Customers who purchase the Powwownow Premium Service. Please

More information

GDPR : We protect your data

GDPR : We protect your data GDPR : We protect your data Dear customer, From the 25th May 2018 the new law of Personal Data Protection (GDPR) will enter into force. At Almagest Wealth Management S.A., we understand your need to be

More information

ON24 DATA PROCESSING ADDENDUM

ON24 DATA PROCESSING ADDENDUM ON24 DATA PROCESSING ADDENDUM This Data Processing Addendum ( Addendum ) is entered into by and between ON24 Inc., on behalf of itself and its Affiliates ( ON24 ), and Client, on behalf of itself and its

More information

CLOUDINARY DATA PROCESSING ADDENDUM

CLOUDINARY DATA PROCESSING ADDENDUM CLOUDINARY DATA PROCESSING ADDENDUM This Data Processing Addendum ( DPA ) forms part of the agreement for the subscription by the Customer to the Cloudinary Service ("Subscription Agreement") between Cloudinary

More information

PERSONAL DATA PROCESSOR AGREEMENT

PERSONAL DATA PROCESSOR AGREEMENT 1 PERSONAL DATA PROCESSOR AGREEMENT PARTIES This personal data processor agreement ( Processor Agreement ) has been entered into between: Buyer/Client/Customer ( Controller ), and The company within the

More information

Moxtra, Inc. DATA PROCESSING ADDENDUM

Moxtra, Inc. DATA PROCESSING ADDENDUM Moxtra, Inc. DATA PROCESSING ADDENDUM This Data Processing Addendum ( DPA ) forms a part of the Terms of Service found at http://moxtra.com/terms-of-service/, unless Company has entered into a superseding

More information

EU Data Processing Addendum

EU Data Processing Addendum EU Data Processing Addendum This EU Data Processing Addendum ( Addendum ) is made and entered into by and between AlienVault, Inc., a Delaware corporation ( AlienVault ) and the customer specified in the

More information

GDPR Data Processing Addendum

GDPR Data Processing Addendum GDPR Data Processing Addendum Effective Date 24 May 2018 This Data Processing Addendum for the GDPR (Addendum) is made as of the Effective Date by and between Fresh Relevance Ltd incorporated and registered

More information

Data Processing Addendum

Data Processing Addendum Data Processing Addendum Based on the General Data Protection Regulation (GDPR) and European Commission Decision 2010/87/EU - Standard Contractual Clauses (Processors) This Data Processing Addendum ( DPA

More information

DATA PROCESSING ADDENDUM

DATA PROCESSING ADDENDUM Page 1 of 20 DATA PROCESSING ADDENDUM This Data Processing Addendum ( DPA ) forms a part of the Customer Terms of Service found at https://slack.com/terms-of-service, unless Customer has entered into a

More information

Data Processing Appendix

Data Processing Appendix Data Processing Appendix This Data Processing Appendix (the Appendix ) is attached to and forms part of the Supplier General Terms and Conditions (the Agreement ) between Nebula Oy ( Supplier ) and customer

More information

RBI GDPR DATA PROCESSING ADDENDUM

RBI GDPR DATA PROCESSING ADDENDUM RBI GDPR DATA PROCESSING ADDENDUM 1. SCOPE 1.1. This GDPR Data Processing Addendum ( DPA ) applies to RBI s processing of personal data on Customer s behalf under the Agreement. With regard to such processing,

More information

DATA PROCESSING ADDENDUM

DATA PROCESSING ADDENDUM This Data Processing Addendum (the DPA ) forms part of Telia Bedriftsavtale or other written or electronic agreement between the Parties for the purchase of telecommunication services, and regulates any

More information

DATA PROCESSING ANNEX

DATA PROCESSING ANNEX Page 1 (5) 1 BACKGROUND AND PURPOSE DATA PROCESSING ANNEX 1.1 The terms of this Annex shall apply to the Agreement between Solibri Oy and/or its Subsidiary/Subsidiaries (Solibri Oy and the Subsidiaries

More information

Data Processing Appendix

Data Processing Appendix Company Name* Execution Date *Company name indicated must conform to the name on customer s Master Subscription Agreement executed with SugarCRM. This Data Processing Appendix on the processing of personal

More information

DATA PROCESSING ADDENDUM

DATA PROCESSING ADDENDUM DATA PROCESSING ADDENDUM This Data Processing Addendum ( DPA ) forms part of the End User License and Services Agreement (the Agreement ) between Customer and Ivanti, to reflect the parties agreement about

More information

DATA PROCESSING ADDENDUM

DATA PROCESSING ADDENDUM DATA PROCESSING ADDENDUM This Data Processing Addendum ( DPA ) forms part of the Master Purchase Agreement, Customer Agreement, Channel Partner Agreement, End User License Agreement or other written agreement

More information

DATA PROCESSING ADENDUM

DATA PROCESSING ADENDUM W www.exponea.com C +421 948 127 332 sales@exponea.com A Exponea, Twin City B, Mlynské Nivy 12 821 09 Bratislava, SK DATA PROCESSING ADENDUM Exponea s.r.o. registered in the Commercial Register maintained

More information

Member Circular March Implementation of the EU General Data Protection Regulation 2016/679 General Guidance to Members

Member Circular March Implementation of the EU General Data Protection Regulation 2016/679 General Guidance to Members Member Circular March 2018 Implementation of the EU General Data Protection Regulation 2016/679 General Guidance to Members Introduction Regulation (EU) 2016/679 containing the General Data Protection

More information

DATA PROCESSING ADDENDUM

DATA PROCESSING ADDENDUM DATA PROCESSING ADDENDUM This Data Processing Addendum ( DPA ) is made between Cognito, LLC., a South Carolina corporation ( Cognito Forms ) and {OrganizationLegalName} ( Customer or Controller or {Organization}

More information

DATA PROTECTION ADDENDUM

DATA PROTECTION ADDENDUM DATA PROTECTION ADDENDUM In the event an agreement ( Underlying Agreement ) entered into by and between (i) either Sunovion Pharmaceuticals Inc. or its subsidiary, Sunovion Pharmaceuticals Europe Ltd.

More information

DATA PROCESSING AGREEMENT

DATA PROCESSING AGREEMENT DATA PROCESSING AGREEMENT This Data Processing Agreement ( DPA or Agreement ), entered into by the CPI customer identified on the applicable CPI services agreement for CPI services ( Customer ) and the

More information

Data Processing Addendum

Data Processing Addendum Data Processing Addendum This Data Processing Addendum ( DPA ) forms part of the Agreement(s) and is entered by and between the Customer and the Service Provider on the Effective Date. For the avoidance

More information

IRIS Group of Companies Customer Data Processing Terms

IRIS Group of Companies Customer Data Processing Terms IRIS Group of Companies Customer Data Processing Terms Definitions (any other capitalised terms not contained in this section will be as defined in the IRIS Software Group General Terms & Conditions (

More information

URBAN AIRSHIP DATA PROCESSING ADDENDUM with EU Standard Contractual Clauses. (Revised September 2017)

URBAN AIRSHIP DATA PROCESSING ADDENDUM with EU Standard Contractual Clauses. (Revised September 2017) URBAN AIRSHIP DATA PROCESSING ADDENDUM with EU Standard Contractual Clauses (Revised September 2017) This Data Processing Addendum ( Addendum ) forms part of the Master Subscription Agreement or the online

More information

DATA PROCESSING AGREEMENT

DATA PROCESSING AGREEMENT DATA PROCESSING AGREEMENT This Data Processing Agreement (the DPA ), entered into by the Customer and the company Ganttic OÜ (company registration number 11979702) having its registered office at Lai tn

More information

DATA PROCESSING ADDENDUM (INCLUDING EU STANDARD CONTRACTUAL CLAUSES)

DATA PROCESSING ADDENDUM (INCLUDING EU STANDARD CONTRACTUAL CLAUSES) DATA PROCESSING ADDENDUM (INCLUDING EU STANDARD CONTRACTUAL CLAUSES) This Data Processing Addendum ( DPA ) shall become effective without any further action by the parties: (a) if Customer signing this

More information

AppLovin Data Processing Agreement

AppLovin Data Processing Agreement AppLovin Data Processing Agreement This AppLovin Data Processing Agreement ( DPA ) is incorporated into and is subject to the AppLovin Terms of Use Agreement available at https://www.applovin.com/terms

More information

Data Processing Addendum

Data Processing Addendum Data Processing Addendum This Data Processing Addendum (" DPA "), forms part of the Agreement or other written or electronic agreement between Pleo Technologies ApS (" Pleo ) and Customer for the purchase

More information

GROUP PRIVACY POLICY. Adopted June 20th, 2017 by each of the Boards of Carnegie Holding AB and Carnegie Investment Bank AB (publ).

GROUP PRIVACY POLICY. Adopted June 20th, 2017 by each of the Boards of Carnegie Holding AB and Carnegie Investment Bank AB (publ). GROUP PRIVACY POLICY Adopted June 20th, 2017 by each of the Boards of Carnegie Holding AB and Carnegie Investment Bank AB (publ). 1 PURPOSE AND SCOPE 1.1 The aim of this policy is to establish uniform,

More information

Twilio Data Protection Addendum ( DPA ) (GDPR, Binding Corporate Rules, Privacy Shield, and Standard Contractual Clauses) (Revision June 2018)

Twilio Data Protection Addendum ( DPA ) (GDPR, Binding Corporate Rules, Privacy Shield, and Standard Contractual Clauses) (Revision June 2018) Twilio Data Protection Addendum ( DPA ) (GDPR, Binding Corporate Rules, Privacy Shield, and Standard Contractual Clauses) (Revision June 2018) Once fully executed, this DPA forms a part of the agreement

More information

DATA HANDLING AGREEMENT

DATA HANDLING AGREEMENT DATA HANDLING AGREEMENT This agreement is for the provision of the transfer of school data between the School, Wonde and approved third party applications. Wonde Ltd a company registered in England under

More information

Privacy Policy. This privacy policy shall be valid even if you have reserved your transfers through the other sales partners of Plus Group Kft.

Privacy Policy. This privacy policy shall be valid even if you have reserved your transfers through the other sales partners of Plus Group Kft. Privacy Policy Plus Group Kft. (1033 Budapest, Polgár utca 8-10., www.plusairsolutions.com, informationsecurity@plusairsolutions.com, tax number: 22976309-2-41, hereinafter: Plus Group Kft., service provider

More information

DATA PROCESSING ADDENDUM (v1.0)

DATA PROCESSING ADDENDUM (v1.0) DATA PROCESSING ADDENDUM (v1.0) Progressive Voice Services Limited trading as Meetupcall of Premier House, Carolina Court, Doncaster, DN45RA ( Meetupcall ) and having its place of business at, ( Customer

More information

DATA PROCESSING ADDENDUM

DATA PROCESSING ADDENDUM DATA PROCESSING ADDENDUM Based on the General Data Protection Regulation (GDPR) and European Commission Decision 2010/87/EU - Standard Contractual Clauses (Processors) This Data Processing Addendum ( DPA

More information

Customer GDPR Data Processing Agreement

Customer GDPR Data Processing Agreement Customer GDPR Data Processing Agreement This Customer Data Processing Agreement reflects the requirements of the European Data Protection Regulation ( GDPR ) as it comes into effect on May 25, 2018. Bench

More information

Customer GDPR Data Processing Agreement

Customer GDPR Data Processing Agreement Customer GDPR Data Processing Agreement Version May 2018 This Customer Data Processing Agreement reflects the requirements of the European Data Protection Regulation ( GDPR ) as it comes into effect on May

More information

GDPR Data Processing Addendum (DPA) Instructions for Area 1 Security Customers

GDPR Data Processing Addendum (DPA) Instructions for Area 1 Security Customers Area 1 Security, Inc. 142 Stambaugh Street Redwood City, CA 94063 EU GDPR DPA GDPR Data Processing Addendum (DPA) Instructions for Area 1 Security Customers Who should execute this DPA: If you qualify

More information

DATA PROCESSING ADDENDUM (GDPR and EU Standard Contractual Clauses)

DATA PROCESSING ADDENDUM (GDPR and EU Standard Contractual Clauses) DATA PROCESSING ADDENDUM (GDPR and EU Standard Contractual Clauses) Rev. 1 May 2018 This Data Processing Addendum ( DPA ) forms part of the product or services agreement ( Agreement ) or other written

More information

CUSTOMER DATA PROCESSING ADDENDUM

CUSTOMER DATA PROCESSING ADDENDUM CUSTOMER DATA PROCESSING ADDENDUM This Data Processing Addendum ( DPA ) and applicable Attachments apply when HP acts as a Data Processor and processes Customer Personal Data on behalf of Customer in order

More information

Licence Agreement

Licence Agreement Licence Agreement EXTERNAL 22 May 2018 Version: 07.00w ------------------- T +44 (0)1206 872143 E collections@ukdataservice.ac.uk www.ukdataservice.ac.uk -------------------... WE ARE SUPPORTED BY THE

More information

ROSETTA STONE LTD. PROCESSING ADDENDUM

ROSETTA STONE LTD. PROCESSING ADDENDUM ROSETTA STONE LTD. PROCESSING ADDENDUM This Data Processing Addendum (this DPA ) forms part of the order document(s) (each a Service Order ) and Services Agreement (collectively, the Agreement ), entered

More information

DATA HANDLING AGREEMENT

DATA HANDLING AGREEMENT DATA HANDLING AGREEMENT This agreement records the terms upon which Wonde will process the School Data for the purpose of transferring the School Data to one or more third party providers of services to

More information

Broadbean Technology Limited - Data Processing Agreement (25th May 2018)

Broadbean Technology Limited - Data Processing Agreement (25th May 2018) Broadbean Technology Limited - Data Processing Agreement (25th May 2018) This agreement and its associated schedules shall come into force with effect from 25 th May 2018 and shall from that date replace

More information

Appropriate Policy Document

Appropriate Policy Document Appropriate Policy Document Schedule 1, Part 4, Data Protection Act 2018 July 2018 Privacy Notice - Appropriate Policy Document v2.docx Page 1 of 8 Contents 1 Introduction... 3 2 Relevant Schedule 1 conditions

More information

DATA PROCESSING ADDENDUM

DATA PROCESSING ADDENDUM DATA PROCESSING ADDENDUM (European Union GDPR) (May 2018) This Data Processing Addendum ( DPA ) forms part of the Pancake Laboratories Inc, DBA ShortStack.com ( ShortStack) Terms and Conditions (https://www.shortstack.com/terms-andconditions/),

More information

Data Processing Agreement and Privacy Policy (EU) Classification: PUBLIC March 2018

Data Processing Agreement and Privacy Policy (EU) Classification: PUBLIC March 2018 1. PURPOSE AND SCOPE 1.1 This document sets out Fourth s Data Processing Agreement and Privacy Policy for its Customers with operations in the EU and/or who process Personal Data of data subjects located

More information

DATA PROCESSING ADDENDUM

DATA PROCESSING ADDENDUM DATA PROCESSING ADDENDUM This Data Processing Addendum ( DPA ) forms a part of the Databricks Terms of Service found at https://www.databricks.com/termsofservice, unless Subscriber has entered into a superseding

More information

Lifesize, Inc. Data Processing Addendum

Lifesize, Inc. Data Processing Addendum Last updated May 1, 2018 Lifesize, Inc. Data Processing Addendum This Lifesize, Inc. Data Processing Addendum ( Addendum ) forms part of the Terms of Service (the Agreement ) between Lifesize, Inc. ( Lifesize

More information

IDEXX - DATA PROTECTION AGREEMENT

IDEXX - DATA PROTECTION AGREEMENT IDEXX - DATA PROTECTION AGREEMENT (A) (B) (C) (D) IDEXX and Customer have entered into an Agreement. In the context of the Agreement, IDEXX will process Personal Data on behalf of and for the benefit of

More information

DATA PROCESSING AGREEMENT (GDPR, Privacy Shield, and Standard Contractual Clauses)

DATA PROCESSING AGREEMENT (GDPR, Privacy Shield, and Standard Contractual Clauses) DATA PROCESSING AGREEMENT (GDPR, Privacy Shield, and Standard Contractual Clauses) This Data Processing Agreement ("DPA") forms part of the Master Services and Subscription Agreement between Customer and

More information

EU GDPR DATA PROCESSING ADDENDUM INSTRUCTIONS FOR CLOUDFLARE CUSTOMERS

EU GDPR DATA PROCESSING ADDENDUM INSTRUCTIONS FOR CLOUDFLARE CUSTOMERS EU GDPR DATA PROCESSING ADDENDUM INSTRUCTIONS WHO SHOULD EXECUTE THIS DPA: FOR CLOUDFLARE CUSTOMERS If you have determined that you qualify as a data controller under the GDPR, and need a data processing

More information

DATA PROCESSING AGREEMENT ( AGREEMENT )

DATA PROCESSING AGREEMENT ( AGREEMENT ) DATA PROCESSING AGREEMENT ( AGREEMENT ) entered into on by and between: with its registered office in Gdańsk (80-387), ul. Arkońska 6, bud. A4, entered in the Register of Enterprises of the National Court

More information

Personal Data. Protection Policy

Personal Data. Protection Policy Personal Data Protection Policy Version 1 May 2018 Contents Terms Definitions... 3 1. Objective and Scope... 4 2. What are Personal Data?... 4 3. Who are affected by Personal Data Processing?... 4 4. What

More information

Data Processing Addendum

Data Processing Addendum Data Processing Addendum Based on the General Data Protection Regulation (GDPR) This Data Processing Addendum ( Addendum ) forms part of your relevant Planet estream terms and conditions, defined as an

More information

Data Processing Agreement

Data Processing Agreement Data Processing Agreement This Data Processing Agreement with EU Standard Contractual Clauses (Processors), (the DPA ) supplements the Dropbox Business Agreement between Dropbox, Inc. and Dropbox International

More information

The GDPR how to prepare MiFID II where are we now? Wednesday 21 February 2018

The GDPR how to prepare MiFID II where are we now? Wednesday 21 February 2018 The GDPR how to prepare MiFID II where are we now? Wednesday 21 February 2018 GDPR so far The EU General Data Protection Regulation (Regulation (EU) 2016/679) comes into effect on 25 May 2018 Aims to protect:

More information

Data Protection Agreement

Data Protection Agreement Data Protection Agreement This Data Protection Agreement (the DPA ) becomes effective on May 25, 2018. The Customer shall make available to GURTAM and the Customer authorizes GURTAM to process information

More information

Data Processing Agreement

Data Processing Agreement Data Processing Agreement New Day at Work Online workspace of the future! Page 1 Content 1. Definitions... 3 2. Scope... 3 3. Our obligations as a Data Processor... 4 4. Your obligations as a Data Controller...

More information

DATA PROCESSING TERMS DEFINITIONS

DATA PROCESSING TERMS DEFINITIONS DATA PROCESSING TERMS DEFINITIONS Agency: means KTS Events Limited (company registration number 05289039) and any business entity from time to time controlling, controlled by, or under common control or

More information

Rigor, Inc. GDPR Data Processing Addendum

Rigor, Inc. GDPR Data Processing Addendum Rigor, Inc. GDPR Data Processing Addendum This GDPR Data Processing Addendum, including the Standard Contractual Clauses referenced herein ( DPA ), supplements any existing and currently valid Rigor license

More information

DATA PROCESSING ADDENDUM (GDPR, Salesforce Processor Binding Corporate Rules, Privacy Shield, and Standard Contractual Clauses) (Revision April 2018)

DATA PROCESSING ADDENDUM (GDPR, Salesforce Processor Binding Corporate Rules, Privacy Shield, and Standard Contractual Clauses) (Revision April 2018) DATA PROCESSING ADDENDUM (GDPR, Salesforce Processor Binding Corporate Rules, Privacy Shield, and Standard Contractual Clauses) (Revision April 2018) This Data Processing Addendum ( DPA ) forms part of

More information

Data Transfer Policy Version 1.1 Last amended: 18 September 2014 Policy Owner: Governance Team

Data Transfer Policy Version 1.1 Last amended: 18 September 2014 Policy Owner: Governance Team Data Transfer Policy Version 1.1 Last amended: 18 September 2014 Policy Owner: Governance Team The University of Nottingham ( the University ) Tri-Campus Data Transfer Policy Background and Statement of

More information

Data Processing Addendum

Data Processing Addendum Data Processing Addendum The parties conclude this Data Processing Addendum ( DPA ), which forms part of the Agreement between Customer and Supplier ( Epignosis ), to reflect our agreement about the Processing

More information

ADDSECURES WAY OF PROCESSING PERSONAL DATA

ADDSECURES WAY OF PROCESSING PERSONAL DATA Agreement Preface ADDSECURES WAY OF PROCESSING PERSONAL DATA For the processing of personal data that AddSecure performs on behalf of its customers, AddSecure becomes a Personal Data Processor. If you

More information

Banks Sheridan Limited Data Protection Privacy Policy 19 May 2018

Banks Sheridan Limited Data Protection Privacy Policy 19 May 2018 Banks Sheridan Limited Data Protection Privacy Policy 19 May 2018 1. Introduction This Policy sets out the obligations of Banks Sheridan Limited ( the Company ) regarding data protection and the rights

More information

All Sorts UK Limited Data Protection Policy 17 th May 2018

All Sorts UK Limited Data Protection Policy 17 th May 2018 All Sorts UK Limited Data Protection Policy 17 th May 2018 1. Introduction This Policy sets out the obligations of All Sorts UK Limited, a company registered in England under number 03534972, whose registered

More information

HIPAA BUSINESS ASSOCIATE AGREEMENT BUSINESS ASSOCIATES AND SUBCONTRACTORS

HIPAA BUSINESS ASSOCIATE AGREEMENT BUSINESS ASSOCIATES AND SUBCONTRACTORS HIPAA BUSINESS ASSOCIATE AGREEMENT BUSINESS ASSOCIATES AND SUBCONTRACTORS This HIPAA Business Associate Agreement ( BAA ) is entered into on this day of, 20 ( Effective Date ), by and between Allscripts

More information

DATA PROTECTION NOTICE

DATA PROTECTION NOTICE DATA PROTECTION NOTICE Who are we? We are the Trustees of the Pension Scheme for the Nursing and Midwifery Council and Associated Employers (the Scheme). We collect, hold and use personal information to

More information

The Controller and Processor Data Protection Binding Corporate Rules of BMC Software

The Controller and Processor Data Protection Binding Corporate Rules of BMC Software The Controller and Processor Data Protection Binding Corporate Rules of BMC Software 4 August 2015 Table of Contents Introduction 2 PART I: BACKGROUND AND ACTIONS 3 PART II: BMC AS A CONTROLLER 5 PART

More information

DATA PROCESSING ADDENDUM FOR CUSTOMERS AND USER OF AEROHIVE PRODUCTS AND SERVICES. Version May 2018

DATA PROCESSING ADDENDUM FOR CUSTOMERS AND USER OF AEROHIVE PRODUCTS AND SERVICES. Version May 2018 DATA PROCESSING ADDENDUM FOR CUSTOMERS AND USER OF AEROHIVE PRODUCTS AND SERVICES 1. Scope and Order of Precedence Version May 2018 This Data Processing Addendum (this DPA ) is deemed an addendum to the

More information

THE UNIVERSITY, CAMBRIDGE IN AMERICA AND THE COLLEGES DATA SHARING PROTOCOL

THE UNIVERSITY, CAMBRIDGE IN AMERICA AND THE COLLEGES DATA SHARING PROTOCOL THE UNIVERSITY, CAMBRIDGE IN AMERICA AND THE COLLEGES DATA SHARING PROTOCOL THIS PROTOCOL is dated 2018 BETWEEN (1) The Chancellor, Masters, and Scholars of the University of Cambridge of The Old Schools,

More information

Amgen Binding Corporate Rules (BCRs) Public Document

Amgen Binding Corporate Rules (BCRs) Public Document Amgen Binding Corporate Rules (BCRs) Public Document Introduction: Amgen is a biotechnology leader committed to serving patients with grievous illness. Binding Corporate Rules (BCRs) express Amgen s commitment

More information

SUMMARY OF BINDING CORPORATE RULES

SUMMARY OF BINDING CORPORATE RULES SUMMARY OF BINDING CORPORATE RULES July 1 st, 2015 1 Table of Contents 1. Preamble... 3 2. Definitions... 3 3. Endorsement... 4 4. Entity with delegated data protection responsibilities... 4 5. Description

More information

HOW TO REGISTER ON THE OECD ESOURCING PORTAL

HOW TO REGISTER ON THE OECD ESOURCING PORTAL HOW TO REGISTER ON THE OECD ESOURCING PORTAL Bidder - User Guide OECD all rights reserved Create your Organisation Profile Access the esourcing Portal following the link: https://oecd.bravosolution.com

More information

BASWARE PERSONAL DATA PROCESSING APPENDIX

BASWARE PERSONAL DATA PROCESSING APPENDIX This Basware personal data processing appendix and its annexes ( DPA ) is an appendix to, and legally binding only in connection with, the sales agreement between Basware and Customer with regard to Basware

More information

Man and Machine - Data Protection Policy

Man and Machine - Data Protection Policy Man and Machine - Data Protection Policy 1. Introduction This Policy sets out the obligations of Man and Machine Ltd, whose registered office is at Unit 8 Thame 40, Jane Morbey Road, Thame, Oxfordshire,

More information

Agreement relating to Data protection in conjunction with the use of the Fujitsu K 5 Cloud

Agreement relating to Data protection in conjunction with the use of the Fujitsu K 5 Cloud Agreement relating to Data protection in conjunction with the use of the Fujitsu K 5 Cloud between Fujitsu Technology Solutions GmbH, Mies-van-der-Rohe-Street 8, 80807 Munich, Germany hereinafter referred

More information

LETTER OF UNDERTAKING FOR CASH MANAGEMENT PRE-AUTHORIZED DEBITS

LETTER OF UNDERTAKING FOR CASH MANAGEMENT PRE-AUTHORIZED DEBITS LETTER OF UNDERTAKING FOR CASH MANAGEMENT PRE-AUTHORIZED DEBITS This Agreement is made between RBC Direct Investing Inc. (the Sponsoring Member ) and the undersigned client of the Sponsoring Member whose

More information

KISS COMPANIES: TERMS AND CONDITIONS OF SUPPLY. NOTE: Your attention is particularly drawn to the contents of clause 13.

KISS COMPANIES: TERMS AND CONDITIONS OF SUPPLY. NOTE: Your attention is particularly drawn to the contents of clause 13. KISS COMPANIES: TERMS AND CONDITIONS OF SUPPLY NOTE: Your attention is particularly drawn to the contents of clause 13. 1. INTERPRETATION 1.1 The following definitions are used in these Conditions: "Business

More information

BP Plus Terms and Conditions

BP Plus Terms and Conditions BP Plus Terms and Conditions 1. Terms and Conditions Binding. By applying for or first using the BP Plus Card, the Customer acknowledges acceptance of these terms and conditions and ensures their observance

More information

DATA PROCESSING ADDENDUM with EU Standard Contractual Clauses

DATA PROCESSING ADDENDUM with EU Standard Contractual Clauses DATA PROCESSING ADDENDUM with EU Standard Contractual Clauses This Data Processing Addendum ("Addendum") forms part of the Agreement between Snow and Company (each as defined below). This Addendum is only

More information

Mastercard Switch Rules

Mastercard Switch Rules Mastercard Switch Rules 1 March 2018 MCSR Applicability of Rules in this Manual Applicability of Rules in this Manual This manual contains the specifications and other Standards applicable when a Network

More information

LOCAL GOVERNMENT ASSOCIATION TEMPLATE MEMORANDUM OF UNDERSTANDING FOR LGPS FUNDS

LOCAL GOVERNMENT ASSOCIATION TEMPLATE MEMORANDUM OF UNDERSTANDING FOR LGPS FUNDS LOCAL GOVERNMENT ASSOCIATION TEMPLATE MEMORANDUM OF UNDERSTANDING FOR LGPS FUNDS 1. This template memorandum of understanding has been prepared for the Local Government Association. We understand that

More information

Data Processing Agreement

Data Processing Agreement Data Processing Agreement between Customer and SmartRecruiters Inc. 225 Bush Street Suite #300 San Francisco CA 94104 - hereinafter SmartRecruiters - both Customer and SmartRecruiters hereinafter individually

More information

* Corporation General Partnership Limited Partnership LLC Sole Proprietorship Non Profit Other Accounts Payable: Name

* Corporation General Partnership Limited Partnership LLC Sole Proprietorship Non Profit Other Accounts Payable: Name INVACARE CORPORATION New Customer Change of Ownership Customer Credit Application *Legal Name of Business Trade Name (DBA) *Billing Address: Shipping Address (if different): *Federal Tax ID # * # of Years

More information

TERMS AND CONDITIONS GOVERNING CORPORATE INTERNET BANKING SERVICE

TERMS AND CONDITIONS GOVERNING CORPORATE INTERNET BANKING SERVICE TERMS AND CONDITIONS GOVERNING CORPORATE INTERNET BANKING SERVICE 1. DEFINITIONS AND INTERPRETATION 1.1 In this Terms and Conditions, except to the extent that the context requires otherwise, the following

More information

HIPAA BUSINESS ASSOCIATE AGREEMENT

HIPAA BUSINESS ASSOCIATE AGREEMENT HIPAA BUSINESS ASSOCIATE AGREEMENT This Agreement, dated as of, 2018 ("Agreement"), by and between, on its own behalf and on behalf of all entities controlling, under common control with or controlled

More information

TWILIO INC. EC DATA PROTECTION AGREEMENT

TWILIO INC. EC DATA PROTECTION AGREEMENT EUROPEAN CUSTOMERS WHO CHOOSE TO ENTER INTO THIS AGREEMENT MUST: 1. Complete all appropriate blanks throughout the agreement. 2. Print and sign agreement. 3. Send a copy of the agreement to Twilio by email

More information

MentorcliQ Data Processing Agreement

MentorcliQ Data Processing Agreement MentorcliQ Data Processing Agreement This MentorcliQ Data Processing Agreement ( DPA ), that includes the Standard Contractual Clauses adopted by the European Commission, as applicable, reflects the parties

More information

Main Street Bank EXTERNAL FUNDS TRANSFER AGREEMENT

Main Street Bank EXTERNAL FUNDS TRANSFER AGREEMENT Main Street Bank EXTERNAL FUNDS TRANSFER AGREEMENT ACCEPTANCE OF TERMS This Agreement sets out the terms and conditions (Terms) upon which Main Street Bank (Bank) will provide the ability to perform external

More information

AWS GDPR DATA PROCESSING ADDENDUM

AWS GDPR DATA PROCESSING ADDENDUM AWS GDPR DATA PROCESSING ADDENDUM This Data Processing Addendum ( DPA ) is an agreement between Amazon Web Services, Inc. ( AWS, we, us, or our ) and you or the entity you represent ( Customer, you or

More information

Episerver Data Processing Agreement

Episerver Data Processing Agreement 1 /12 Episerver Data Processing Agreement Last Modified: May 30, 2017 As referred to in Section 7 of the Episerver End-User Services Agreement ( E ), for the purposes of Article 26(2) of Directive 95/46/EC,

More information

ACCESS REQUEST AGREEMENT

ACCESS REQUEST AGREEMENT ACCESS REQUEST AGREEMENT This Access Request Agreement (this Agreement ) is entered into as of this day of, 20 by and between Black Hills Gas, LLC, a Delaware limited liability company ( Black Hills )

More information

BUSINESS ASSOCIATE AGREEMENT W I T N E S S E T H:

BUSINESS ASSOCIATE AGREEMENT W I T N E S S E T H: BUSINESS ASSOCIATE AGREEMENT THIS BUSINESS ASSOCIATE AGREEMENT ( this Agreement ) is made and entered into as of this day of 2015, by and between TIDEWELL HOSPICE, INC., a Florida not-for-profit corporation,

More information

4. To receive the Service you must meet the following requirements:

4. To receive the Service you must meet the following requirements: The vehicle licence renewal assistance described below ( the Service ) provided by The Standard Bank of South Africa Limited ( we /us / our ) is subject to the following terms and conditions: 1. You must

More information

Standard Terms and Conditions Pay Direct Service ( PDS )

Standard Terms and Conditions Pay Direct Service ( PDS ) Standard Terms and Conditions - PDS_published 15.07.15.pdf 2015 Bottomline Technologies (de), Inc. Definitions Standard Terms and Conditions Pay Direct Service ( PDS ) 24/7 24 hours a day, 7 days a week,

More information